2017-04-17 20:28:47

by guido

[permalink] [raw]
Subject: [refpolicy] [PATCH] corecommands: new file contexts for Gnome applications

This patch adds three new file contexts for script executables
belonging to new Gnome applications (weather application and
sound recorder).

Signed-off-by: Guido Trentalancia <[email protected]>
---
policy/modules/kernel/corecommands.fc | 3 +++
1 file changed, 3 insertions(+)

--- a/policy/modules/kernel/corecommands.fc 2016-12-28 20:30:19.000000000 +0100
+++ b/policy/modules/kernel/corecommands.fc 2017-04-17 22:18:40.644373042 +0200
@@ -322,12 +322,15 @@ ifdef(`distro_gentoo',`
/usr/share/gedit-2/plugins/externaltools/tools(/.*)? gen_context(system_u:object_r:bin_t,s0)
/usr/share/gitolite/hooks/common/update -- gen_context(system_u:object_r:bin_t,s0)
/usr/share/gitolite/hooks/gitolite-admin/post-update -- gen_context(system_u:object_r:bin_t,s0)
+/usr/share/gnome-sound-recorder/org.gnome.SoundRecorder -- gen_context(system_u:object_r:bin_t,s0)
/usr/share/gnucash/finance-quote-check -- gen_context(system_u:object_r:bin_t,s0)
/usr/share/gnucash/finance-quote-helper -- gen_context(system_u:object_r:bin_t,s0)
/usr/share/hal/device-manager/hal-device-manager -- gen_context(system_u:object_r:bin_t,s0)
/usr/share/hal/scripts(/.*)? gen_context(system_u:object_r:bin_t,s0)
/usr/share/mc/extfs/.* -- gen_context(system_u:object_r:bin_t,s0)
/usr/share/Modules/init(/.*)? gen_context(system_u:object_r:bin_t,s0)
+/usr/share/org.gnome.Weather/org.gnome.Weather.Application -- gen_context(system_u:object_r:bin_t,s0)
+/usr/share/org.gnome.Weather/org.gnome.Weather.BackgroundService -- gen_context(system_u:object_r:bin_t,s0)
/usr/share/printconf/util/print\.py -- gen_context(system_u:object_r:bin_t,s0)
/usr/share/PackageKit/pk-upgrade-distro\.sh -- gen_context(system_u:object_r:bin_t,s0)
/usr/share/PackageKit/helpers(/.*)? gen_context(system_u:object_r:bin_t,s0)


2017-04-19 01:49:50

by Chris PeBenito

[permalink] [raw]
Subject: [refpolicy] [PATCH] corecommands: new file contexts for Gnome applications

On 04/17/2017 04:28 PM, Guido Trentalancia via refpolicy wrote:
> This patch adds three new file contexts for script executables
> belonging to new Gnome applications (weather application and
> sound recorder).
>
> Signed-off-by: Guido Trentalancia <[email protected]>
> ---
> policy/modules/kernel/corecommands.fc | 3 +++
> 1 file changed, 3 insertions(+)
>
> --- a/policy/modules/kernel/corecommands.fc 2016-12-28 20:30:19.000000000 +0100
> +++ b/policy/modules/kernel/corecommands.fc 2017-04-17 22:18:40.644373042 +0200
> @@ -322,12 +322,15 @@ ifdef(`distro_gentoo',`
> /usr/share/gedit-2/plugins/externaltools/tools(/.*)? gen_context(system_u:object_r:bin_t,s0)
> /usr/share/gitolite/hooks/common/update -- gen_context(system_u:object_r:bin_t,s0)
> /usr/share/gitolite/hooks/gitolite-admin/post-update -- gen_context(system_u:object_r:bin_t,s0)
> +/usr/share/gnome-sound-recorder/org.gnome.SoundRecorder -- gen_context(system_u:object_r:bin_t,s0)
> /usr/share/gnucash/finance-quote-check -- gen_context(system_u:object_r:bin_t,s0)
> /usr/share/gnucash/finance-quote-helper -- gen_context(system_u:object_r:bin_t,s0)
> /usr/share/hal/device-manager/hal-device-manager -- gen_context(system_u:object_r:bin_t,s0)
> /usr/share/hal/scripts(/.*)? gen_context(system_u:object_r:bin_t,s0)
> /usr/share/mc/extfs/.* -- gen_context(system_u:object_r:bin_t,s0)
> /usr/share/Modules/init(/.*)? gen_context(system_u:object_r:bin_t,s0)
> +/usr/share/org.gnome.Weather/org.gnome.Weather.Application -- gen_context(system_u:object_r:bin_t,s0)
> +/usr/share/org.gnome.Weather/org.gnome.Weather.BackgroundService -- gen_context(system_u:object_r:bin_t,s0)
> /usr/share/printconf/util/print\.py -- gen_context(system_u:object_r:bin_t,s0)
> /usr/share/PackageKit/pk-upgrade-distro\.sh -- gen_context(system_u:object_r:bin_t,s0)
> /usr/share/PackageKit/helpers(/.*)? gen_context(system_u:object_r:bin_t,s0)

Merged. I added escaping.

--
Chris PeBenito